Back to library
Cyber · Issued by SEI (Software Engineering Institute), Carnegie Mellon University

OCTAVE

Operationally Critical Threat, Asset, and Vulnerability Evaluation

asset-centricthreat modelingself-assessmentOCTAVE AllegroSEIoperational risk
Compare OCTAVE with

Self-directed risk assessment methodology enabling organizations to identify critical assets, threats, and vulnerabilities through facilitated workshops.

Developed by Carnegie Mellon's SEI, OCTAVE empowers cross-functional teams to conduct risk assessments without heavy reliance on external consultants. It emphasizes organizational context, focusing on people, processes, and technology. OCTAVE Allegro, a streamlined variant, suits smaller teams and accelerated timelines. A manufacturing firm might use OCTAVE to map threats to SCADA systems and prioritize hardening controls. The approach fosters risk ownership across business units.

At a glance

Complexity
Medium
Certification
No (guideline)
Time to implement
3–6 months
Issued by
SEI (Software Engineering Institute), Carnegie Mellon University

Fits

Industries
manufacturingenergygovernmenthealthcareitbanking
Risk types
cyberoperationalstrategic
See if it fits you

Run the Finder to get a personalised match score for OCTAVE.

Made with Emergent